CVE-2020-25660
- EPSS 0.27%
- Veröffentlicht 23.11.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:23
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the ...
CVE-2020-25725
- EPSS 0.18%
- Veröffentlicht 21.11.2020 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:35
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't corr...
CVE-2020-20739
- EPSS 0.2%
- Veröffentlicht 20.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:15
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
CVE-2020-20740
- EPSS 0.36%
- Veröffentlicht 20.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:15
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
CVE-2020-13671
- EPSS 4.5%
- Veröffentlicht 20.11.2020 16:15:15
- Zuletzt bearbeitet 03.11.2025 18:06:21
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affec...
CVE-2020-4788
- EPSS 0.2%
- Veröffentlicht 20.11.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:15
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
CVE-2020-28924
- EPSS 0.35%
- Veröffentlicht 19.11.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:23:18
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on th...
CVE-2020-28941
- EPSS 0.06%
- Veröffentlicht 19.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:20
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an i...
CVE-2020-28948
- EPSS 73.73%
- Veröffentlicht 19.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:21
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
CVE-2020-28949
- EPSS 92.96%
- Veröffentlicht 19.11.2020 19:15:11
- Zuletzt bearbeitet 07.11.2025 22:03:27
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.